{"id":"CVE-2026-59711","aliases":["GHSA-cr32-g25g-vxjj"],"url":"https://o3.security/vulnerability/CVE-2026-59711","summary":"showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLDocument","details":"showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.","published":"2026-07-06T21:00:38.491Z","modified":"2026-08-19T21:41:59.616958826Z","cvss":null,"epss":{"score":0.00327,"percentile":0.25851,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"showdown","fixedVersion":null}],"fix":{"url":"https://github.com/showdownjs/showdown/commit/184a3e4e97f90e075c4512f2c4c06dcf655e91b7","label":"showdownjs/showdown@184a3e4"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59711.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59711"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/showdown-cross-site-scripting-via-unescaped-metadata-title-in-completehtmldocument"},{"type":"REPORT","url":"https://github.com/showdownjs/showdown/issues/1047"},{"type":"PACKAGE","url":"https://github.com/showdownjs/showdown"},{"type":"WEB","url":"https://github.com/showdownjs/showdown/commit/184a3e4e97f90e075c4512f2c4c06dcf655e91b7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T21:41:59.616958826Z"}}